Data residency and compliance
We do not offer region-only hosting or regional data residency today, so you cannot select a hosting region or receive a guarantee that customer data stays within a named country or region.
Topic | Current commitment |
|---|---|
Regional hosting | Region-only hosting and regional data residency are not available. |
Physical server location | We do not provide a named country or cloud region as a residency option. |
Subprocessors | Listed service providers may process customer or service data for the functions they support. Their individual geographic processing locations are not covered by a regional guarantee. |
Data protection agreement | We can provide a Data Processing Addendum (DPA) for security reviews, vendor due diligence, or DPA requests. |
International transfers | Our privacy terms reference adequacy decisions or Standard Contractual Clauses (SCCs) for applicable transfers involving the EEA, UK, and Switzerland. |
Encryption | We use encryption in transit and at rest. Integration credentials and raw support-ticket message payloads are stored encrypted. |
Access controls | We use strict access controls. Access to Ferndesk is limited to authenticated users and authorized workspace roles. |
Compliance status | We are not currently SOC 2 certified. SOC 2 Type I is in progress. |
How subprocessors affect data handling
Our core service providers support functions such as infrastructure, search, AI generation, billing, email, error monitoring, and telemetry. The Security Overview lists the providers and their supported functions.
Customer-enabled integrations such as GitHub, Zendesk, Intercom, Help Scout, and Slack are separate from our listed subprocessors and are used only when you enable the integration.
Data retention and deletion
Customer content is retained during the subscription and deleted within 30 days of termination or a deletion request, unless a shorter deletion window applies. Backup copies are overwritten within 60 days, while billing, audit, and security logs may be retained longer where required for legal, accounting, or security purposes.
Request a DPA or security review
Contact [email protected] for security reviews, vendor due diligence, or DPA requests.